Aggregator
CVE-2012-5331 | Nasir Khan asaanCart 0.9 index.php page path traversal (EDB-18599 / XFDB-74065)
11 months 4 weeks ago
A vulnerability classified as critical has been found in Nasir Khan asaanCart 0.9. This affects an unknown part of the file index.php. The manipulation of the argument page leads to path traversal.
This vulnerability is uniquely identified as CVE-2012-5331. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2010-3895 | IBM OmniFind 8.0/8.4/8.5/9.0 first access control (EDB-15475 / BID-44740)
11 months 4 weeks ago
A vulnerability has been found in IBM OmniFind 8.0/8.4/8.5/9.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument first leads to improper access controls.
This vulnerability is known as CVE-2010-3895. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-36804 | Atlassian Bitbucket Server and Data Center up to 8.3.0 API command injection (BSERV-13438 / EDB-51040)
11 months 4 weeks ago
A vulnerability was found in Atlassian Bitbucket Server and Data Center up to 8.3.0. It has been rated as critical. This issue affects some unknown processing of the component API. The manipulation leads to command injection.
The identification of this vulnerability is CVE-2022-36804. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-9213 | Linux Kernel up to 4.20.13 Capability Check mm/mmap.c null pointer dereference (openSUSE-SU-2019:1085-1 / EDB-46502)
11 months 4 weeks ago
A vulnerability was found in Linux Kernel up to 4.20.13. It has been rated as problematic. This issue affects some unknown processing of the file mm/mmap.c of the component Capability Check. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2019-9213. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-0172 | elfutils up to 0.158 dwarf_begin_elf.c check_section numeric error (USN-2188-1 / Nessus ID 73802)
11 months 4 weeks ago
A vulnerability, which was classified as critical, was found in elfutils up to 0.158. This affects the function check_section of the file dwarf_begin_elf.c. The manipulation leads to numeric error.
This vulnerability is uniquely identified as CVE-2014-0172. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2014-0162 | OpenStack icehouse Rc-1 Registry input validation (USN-2193-1 / Nessus ID 73972)
11 months 4 weeks ago
A vulnerability was found in OpenStack icehouse Rc-1. It has been rated as critical. This issue affects some unknown processing of the component Registry. The manipulation leads to improper input validation.
The identification of this vulnerability is CVE-2014-0162. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-0173 | Automattic Jetpack up to 2.9.3 access control (Nessus ID 73686 / ID 12944)
11 months 4 weeks ago
A vulnerability was found in Automattic Jetpack. It has been classified as critical. This affects an unknown part. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2014-0173. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-0114 | Oracle Real-Time Decision Server 11.1.1.7 commons-beanutils-1.8.0.jar this input validation (EDB-41690 / Nessus ID 73922)
11 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in Oracle Real-Time Decision Server 11.1.1.7. Affected by this issue is some unknown functionality in the library lib/commons-beanutils-1.8.0.jar of the component Decision Server. The manipulation of the argument this leads to improper input validation.
This vulnerability is handled as CVE-2014-0114. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
HivisionIDPhotos:轻量级的 AI 证件照制作工具
11 months 4 weeks ago
HivisionIDPhotos是什么HivisionIDPhotos 是一款轻量级的 AI 证件照制作工具,旨在通过简便的操作生成标准证件照和六寸排版照。该工具提供了简洁的 Web 界面和 A...
黑海洋
HivisionIDPhotos:轻量级的 AI 证件照制作工具
11 months 4 weeks ago
HivisionIDPhotos是什么HivisionIDPhotos 是一款轻量级的 AI 证件照制作工具,旨在通过简便的操作生成标准证件照和六寸排版照。该工具提供了简洁的 Web 界面和 API
CVE-2005-0989 | Mozilla Firefox 1.0.1/1.0.2 Javascript Lambda Symbol memory corruption (EDB-25334 / Nessus ID 21952)
11 months 4 weeks ago
A vulnerability was found in Mozilla Firefox 1.0.1/1.0.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Javascript Lambda Symbol Handler. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2005-0989. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to disable the affected component.
vuldb.com
CVE-2013-4786 | HP Integrated Lights-Out 2/3/4 IPMI Protocol credentials management (EDB-38633 / Nessus ID 80101)
11 months 4 weeks ago
A vulnerability was found in HP Integrated Lights-Out 2/3/4 and classified as critical. Affected by this issue is some unknown functionality of the component IPMI Protocol Handler. The manipulation leads to credentials management.
This vulnerability is handled as CVE-2013-4786. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to change the configuration settings.
vuldb.com
38C3: Last Minute Assembly Infos
11 months 4 weeks ago
Es wird kuschelig! Weit über 400 Assemblies mit unzähligen tollen Projekten und Ideen haben
CVE-2019-9162 | Linux Kernel up to 4.20.11 SNMP NAT Module nf_nat_snmp_basic_main.c array index (K31864522 / EDB-46477)
11 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 4.20.11. This issue affects some unknown processing of the file net/ipv4/netfilter/nf_nat_snmp_basic_main.c of the component SNMP NAT Module. The manipulation leads to improper validation of array index.
The identification of this vulnerability is CVE-2019-9162. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Загадка квантовой запутанности: как частицы общаются мгновенно
11 months 4 weeks ago
Почему мгновенные корреляции не нарушают скорость света.
CVE-2014-0189 | virt-who cryptographic issues (Bug 1088732 / Nessus ID 81352)
11 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in virt-who. Affected by this issue is some unknown functionality. The manipulation leads to cryptographic issues.
This vulnerability is handled as CVE-2014-0189. Local access is required to approach this attack. There is no exploit available.
vuldb.com
公平CFS调度类:SCHED_NORMAL、SCHED_BATCH和SCHED_IDLE
11 months 4 weeks ago
公平CFS调度类:SCHED_NORMAL、SCHED_BATCH和SCHED_IDLE,它们的相同与不同。
21cnbao
CVE-2014-0225 | Spring Framework up to 3.2.8/4.0.4 XML Document xml external entity reference (Nessus ID 83317 / ID 115111)
11 months 4 weeks ago
A vulnerability has been found in Spring Framework up to 3.2.8/4.0.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the component XML Document Handler. The manipulation leads to xml external entity reference.
This vulnerability is known as CVE-2014-0225. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
软件设计中的七类安全问题
11 months 4 weeks ago
现在的软件正在逐渐定义一切,软件的形态也逐渐多样化,不仅仅是电脑或手机中看到的应用程序或App是软件,硬件设备等很多看不到的地方也正在有软件的构建和参与,比如汽车、电视、飞机、仓库、收银台等等,除了传